Skip to content

HPE6-A87 HPE Networking CX 10000 Exam Practice Questions

Prepare for HPE6-A87 with more than an answer.

150 questions in the full set12 sample questionsUpdated Sep 12, 2026
Level
Not specified on official datasheet
Domains covered on the exam 7
  1. Module 1: HPE Aruba Networking CX 10000 Series with Pensando overview10%
  2. Module 2: Installation and setup Installation10%
  3. Module 3: HPE Aruba Networking Fabric Composer overview and navigation10%
  4. Module 4: Managing network services with HPE Aruba Networking Fabric Composer15%
  5. Module 5: Managing security with HPE Aruba Networking Fabric Composer15%
  6. Module 6: Pensando PSM navigation and security management18%
  7. Module 7: Network monitoring22%
  1. 1

    What is the primary purpose of HPE Aruba Networking Fabric Composer in a CX 10000 environment?

    Show answer details

    Correct answer: C

    HPE Aruba Networking Fabric Composer (AFC) is a software-defined orchestration tool designed to simplify and automate the provisioning of the data center network fabric (such as EVPN-VXLAN) and orchestrate the distributed security policies applied to the CX 10000 DPUs.

  2. 2

    When navigating the HPE Aruba Networking Fabric Composer UI, an administrator needs to configure both the physical switch interconnects and the logical EVPN overlay.

    Which types of networks can Fabric Composer natively configure and manage?

    Show answer details

    Correct answer: B

    Fabric Composer is designed to manage the entire fabric lifecycle. This includes configuring the physical Layer 3 routed underlay (e.g., OSPF or BGP) as well as the logical EVPN-VXLAN overlay networks, providing a unified management approach for modern leaf-spine architectures.

  3. 3

    A security operations team requires access to the Fabric Composer to view firewall rules and telemetry, but they must be prevented from modifying any fabric configurations or switch assignments.

    How should you implement this requirement in Fabric Composer?

    Show answer details

    Correct answer: B

    Fabric Composer supports granular Role-Based Access Control (RBAC). To satisfy the requirement of least privilege, an administrator should create a custom user role that explicitly grants read-only permissions for fabric/network configuration while providing the necessary read (or write, depending on exact needs, though the prompt specifies viewing) permissions for the security and telemetry modules.

    flowchart TD A[User: SecOps] --> B(Custom Role: Security Analyst) B -->|Read Only| C[Fabric/Network Config] B -->|Read/View| D[Security Policies/Telemetry]
  4. 4

    To locate a specific endpoint's connection details (such as MAC, IP, and connected port) within the Fabric Composer UI, an administrator should navigate to the ________ menu.

    Show answer details

    Correct answer: C

    In the Fabric Composer UI, the 'Discovery > Endpoints' (or analogous endpoint visibility screen) is used to view discovered entities connected to the fabric, detailing their MAC addresses, IP addresses, and the specific switch ports they are attached to.

  5. 5

    A network architect is evaluating the HPE Aruba Networking CX 10000 Series switch for a new data center deployment. The primary goal is to provide stateful firewall services at the edge without hair-pinning traffic to a central appliance. Which component within the CX 10000 makes this distributed services architecture possible?

    Show answer details

    Correct answer: B

    The HPE Aruba Networking CX 10000 integrates an AMD Pensando Data Processing Unit (DPU) directly into the switch. This DPU is responsible for delivering stateful software-defined services (like firewalling, IPsec, and telemetry) inline, eliminating the need to hairpin traffic to a centralized security appliance.

  6. 6

    When comparing a traditional centralized data center security model to the distributed services architecture of the CX 10000, which fundamental networking inefficiency is directly resolved by deploying the CX 10000 at the Top of Rack (ToR)?

    Show answer details

    Correct answer: C

    In traditional architectures, East-West traffic between workloads in different subnets (or even the same subnet, for microsegmentation) must be routed to a centralized firewall, creating a 'trombone' or 'hair-pin' effect that consumes core bandwidth and adds latency. The CX 10000 applies stateful policies directly at the ToR, completely eliminating this inefficiency.

    flowchart LR subgraph Traditional A[Server A] --> B[ToR Switch] B --> C[Core] C --> D[Central Firewall] D --> C C --> B B --> E[Server B] end subgraph CX10000 F[Server A] --> G[CX 10000 /w DPU] G --> H[Server B] end

Create an account to continue.